06/02/2026
FBI Alert: New Attack Bypasses Microsoft 365 MFA
A new phishing platform called Kali365 is allowing attackers to hijack Microsoft 365 accounts without stealing credentials—and without triggering MFA. [ic3.gov]
Check out our full bva tech blog at the following link:
https://www.bvainc.com/2026/06/02/new-fbi-alert-kali365-phishing-kit-bypasses-microsoft-365-mfa/
Instead, it tricks users into approving access via legitimate Microsoft login flows, capturing OAuth tokens for persistent access.
What this means:
• MFA alone is no longer enough
• Attackers are targeting identity—not passwords
• Persistent access can go undetected
What you should do now:
• Block or restrict device code authentication
• Review Conditional Access policies
• Monitor OAuth/token activity
If you’re not actively managing identity security in M365, you’re exposed.
BVA can help assess and secure your environment before it’s too late.